


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGe…
Published:
31 August 2026 at 00:00:00
Alert date:
31 August 2026 at 23:17:03
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
A vulnerability has been identified in Soarkey StudentManagement (学生信息管理系统) affecting versions up to commit e08f7f1d5015af407aa4cca0ada3dea189b4937e. The flaw resides in the AdminDao.doGet function within the file code/src/service/AdminDao.java, part of the Administrative Servlet component. By manipulating the 'action' argument, an attacker can achieve authorization bypass remotely. A public exploit is already available, increasing the risk of active exploitation. The project maintainer was notified via a GitHub issue report but has not responded. This is a remotely exploitable, publicly disclosed vulnerability with no known patch or vendor acknowledgment at the time of reporting.
Technical details
Mitigation steps:
Affected products:
Soarkey StudentManagement
学生信息管理系统
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82621
https://github.com/Soarkey/StudentManagement/
https://github.com/Soarkey/StudentManagement/issues/32
https://vuldb.com/cve/CVE-2026-82621
https://vuldb.com/submit/893104
https://vuldb.com/vuln/397121
https://vuldb.com/vuln/397121/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
